ipsec with certificate authentication issue



I have ipsec setup for telnet (transport). I'll leave out all the filter
details as I don't think they are pertinent to the problem. It works fine
with preshared key but I cannot get it to work with certificate
authentication. Client machine is connected to the lan via pptp vpn and
telnet server resides on the remote lan. This works fine with preshared key.
Both machines have my own MS cert server's certificate installed in their
local machine store's trusted root certification authorities folder and both
machines have their own certificate issued from this CA installed in their
own local machine store. The cert was obtained via ms cert services web
interface using the 'administrator' template. But if I understand correctly
the type of cert on each machine does not really matter as long as they are
both from the same trused root CA, which they are.

I'm really not sure where to go from here. I know the issue must be
certificate auth related since it works just fine with preshared key.

any help would be greatly appreciated.


.



Relevant Pages

  • Re: Insurance Certificates Database
    ... table based on a questionnaire, ... We did have a commercial certificate tracking application a while back, ... I agree my Indefinite Cert Fields look like fixed attributes of the ... firm. ...
    (microsoft.public.access.tablesdbdesign)
  • Re: Insurance Certificates Database
    ... I agree my Indefinite Cert Fields look like fixed attributes of the ... piece of data as an attribute of the insurance certificate (excepting firm ID ... The Policies table presents more of a problem than the Certs table, ... I suggested having a different table for each type of policy to solve this ...
    (microsoft.public.access.tablesdbdesign)
  • Re: Insurance Certificates Database
    ... table based on a questionnaire, ... We did have a commercial certificate tracking application a while back, ... breaking the data down into various tables, ie normalization. ... I agree my Indefinite Cert Fields look like fixed attributes of the ...
    (microsoft.public.access.tablesdbdesign)
  • Re: ADFS Token-signing Certs Not in Trusted Root Store
    ... This is good info, Joe. ... So now I know that the token-signing certificate is ... Get a signing cert from a CA ... case, you never have to worry about expiration or CRL checking, as your cert ...
    (microsoft.public.windows.server.active_directory)
  • Re: Issues with SSL on Win CE 5.0
    ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
    (microsoft.public.windowsce.embedded)